First published: Tue Apr 15 2025(Updated: )
Missing Authorization vulnerability in Quý Lê 91 Administrator Z allows Privilege Escalation. This issue affects Administrator Z: from n/a through 2025.03.24.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Administrator | <=2025.03.24 |
Update the WordPress Administrator Z plugin to the latest available version (at least 2025.03.27).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26959 has been classified as a high severity vulnerability due to its potential for privilege escalation.
CVE-2025-26959 allows unauthorized users to escalate their privileges within WordPress Administrator Z, compromising security.
To fix CVE-2025-26959, update your WordPress Administrator Z plugin to a version beyond 2025.03.24.
Any user operating versions of WordPress Administrator Z up to and including 2025.03.24 is vulnerable to CVE-2025-26959.
CVE-2025-26959 is a missing authorization vulnerability that allows for privilege escalation in the Administrator Z plugin.